Malicious Archive / .ZIP — malware analysis report

Static analysis result for SHA-256 d899d52e33145872…

MALICIOUS

Archive / .ZIP

10.45 MB
MD5: 60a5e99a306f05167367ed01ca93423a SHA-1: ad7c59b2a3201c89646fca3f8d20631733f357c5 SHA-256: d899d52e33145872a2ff1255ae74fcfd52ad3b2429b928affa0b8bbf7953d3cd
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1071.001 Web Protocols

The sample is a ZIP archive that was flagged as malicious due to containing a malicious member. The archive entry limit was reached, indicating a potentially large or complex archive. The primary IOC is the SHA256 hash of the malicious member found within the archive.

Heuristics 2

  • Archive contains malicious member critical ARCHIVE_CHILD_MALICIOUS
    At least one extracted archive member was classified as malicious. The archive is a transport wrapper for that payload.
  • Archive entry limit reached (50) info ARCHIVE_LIMIT
    Only the first 50 files were scanned.